首页> 外文会议>European Conference on Information Warfare and Security >The Issues of Software Being Classified as Malicious by Antivirus False Positive Alerts
【24h】

The Issues of Software Being Classified as Malicious by Antivirus False Positive Alerts

机译:通过防病毒假冒积极警报被归类为恶意的软件问题

获取原文

摘要

The continuous development of evolving malware types creates a need to study and understand how antivirus products detect and alert the user. This paper investigates today's antivirus solutions and how their false positive alerts affect the software development and distribution process, which in the long term could even lead to loss of business. It is discussed and demonstrated how antivirus detection deals with bespoke applications and how this can be reversed and manipulated to evade detection, allowing to be used by malicious software developers. The paper also presents ideas that would enable antivirus products to overcome these detection issues without altering their detection engines but by focusing on the developer's source code submission. The potential lack of essential and in most cases obvious steps in malicious software detection is also examined. The paper concludes that the inconsistencies between different antivirus detection engines along with the introduction of reputation based detection, allows more sophisticated and undetectable malicious software to be created and spread.
机译:不断发展的恶意软件类型的发展需要研究和理解防病毒产品如何检测和警告用户。本文调查了今天的防病毒解决方案以及他们的错误积极警报如何影响软件开发和分配过程,从而长期甚至可能导致业务损失。讨论并展示了防病毒检测如何处理定制应用以及如何颠倒和操作以逃避检测,允许被恶意软件开发人员使用。本文还展示了抗病毒产品克服这些检测问题的想法,而不会改变其检测引擎,而是通过专注于开发人员的源代码提交。还检查了潜在缺乏必要的,在大多数情况下,还检查了恶意软件检测中的明显步骤。本文得出结论,不同防病毒检测引擎之间的不一致随着基于声誉的检测,允许创造和传播更复杂和不可检测的恶意软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号